Somebody on your team can already see every gift every household made last year, down to the dollar and the date. Usually that is fine — it is the treasurer, and it is their job. The trouble starts when the boundary around that access was never actually drawn, just assumed, and three or four other people can see the same thing without anyone having decided they should.
Most small churches do not have a staff directory with separate logins and separate permissions. They have one shared login, a treasurer who reconciles the offering, a rotating pair of counters, and a pastor who wants to understand the church's health without wanting to know who gave what. Figuring out who sees what, when the software itself does not draw the line, is a conversation worth having on purpose rather than letting default behavior decide it for you.
Three jobs, three different reasons to look
Start by separating the roles, because they need genuinely different things. The treasurer reconciles deposits against records, answers a giver's question about their own contributions, and produces year-end statements — that requires full access to individual records. Counters verify what came in on a given Sunday: cash, checks, the total. Their job is done once the count matches the deposit; it does not require ongoing access to anyone's giving history. Pastoral staff want to understand trends, respond to a real financial strain, and steward the budget — most of that is served by totals and patterns, not a name-by-name ledger.
Naming these three jobs out loud is most of the work. Once you can say “the treasurer needs individual records, the counters need the total, the pastor needs the trend,” the actual boundary mostly draws itself.
What the treasurer actually needs
Give the treasurer everything: individual contributions, edit and delete on entries when a correction is needed, giving goals, trends, and year-end statements. This is not generosity — it is the job. A treasurer who cannot see a full record cannot reconcile it, cannot answer “did my gift from March get recorded correctly,” and cannot produce a statement a giver can hand to their accountant. The boundary you are drawing is not around the treasurer. It is around everyone else.
The one thing worth writing down even for the treasurer is a norm about looking things up without a reason. Access is not the same as license. A treasurer who only opens a record when reconciling, correcting, or answering a question is behaving exactly as the role requires. A treasurer who browses individual histories out of curiosity is misusing access nobody meant to restrict but also nobody meant as an invitation to browse.
What counters need, and where their job ends
A counter's task is narrow: verify what came in, agree on a total with a second person, and make sure the deposit matches the count. None of that requires seeing whose envelope contained what, once the total is settled. In a lot of churches, counters end up with more visibility than the job requires simply because it is easier to hand them the same screen the treasurer uses rather than build a narrower one.
If your software does not separate these views, the fix is procedural: counters record the total that gets entered, and the treasurer is the one who opens individual records to enter or reconcile them. Two counters verifying a total together is also a safeguard in its own right — it is harder for a number to go missing when two people agreed on it out loud. Keep that discipline even if the software cannot enforce it for you.
What pastoral staff should see, and why it is less than you think
This is the one most churches get wrong by default, not by decision. It is easy for a pastor to end up with full access simply because they are the pastor, and full access includes a name-by-name giving history nobody actually decided they needed. Most pastoral judgment calls — is giving healthy, is it trending down, does the budget need a conversation — are answered by reading giving trends, not by knowing what any one household gave last Tuesday.
There are real exceptions. A pastor may need to know a specific household's giving stopped if that silence is also a pastoral-care signal worth a phone call. That is a legitimate use, and it is different from routine access to everyone's numbers as a matter of habit. The difference is intent: looking at one record because something prompted real concern is not the same as having standing visibility into all of them because nobody drew a line.
The part the software will not do for you
Here is the honest limit: SundayBridge has one login per church. There are no staff roles or permissions, which means the treasurer, the counters, and the pastor are all looking at the same account if they share it, and the software will not stop any of them from opening the giving module. That is true of most tools built for small churches at this price point — the boundary is not a checkbox somewhere. It is an agreement your team keeps.
That is not a reason to give up on the boundary. It is a reason to make it explicit instead of assumed. A church with a written rule — “only the treasurer opens individual giving records; everyone else works from totals and trends” — has a real boundary, even without a permission system enforcing it. A church that hopes good judgment will sort it out has no boundary at all, just an unspoken expectation that eventually someone will violate without meaning to.
Write the rule down before the first awkward question
The best time to decide who sees giving records is before anyone asks “wait, who can see what I give?” A short written policy — two or three sentences, posted somewhere the finance team can find it — does more good than a much longer conversation held under pressure after someone already feels exposed. Name the roles, name what each one can see, and say it plainly to your givers if they ask. Most people do not need an elaborate system. They need to know a human being decided this on purpose.
This is the same instinct behind tracking giving that respects the giver in the first place — the record exists to serve the giver and the church's bookkeeping, not to become something casually browsable by whoever is logged in that week. A record kept with discretion earns trust the same way a well-run count does: quietly, and over time.
What to do when the team is smaller than the roles
Plenty of churches this size do not have three separate people for three separate jobs. The treasurer might also count. The pastor might also reconcile the books in a pinch. When one person wears two hats, the rule still applies — it just means that person is agreeing, in effect, to hold two different levels of access responsibly and to notice when they are wearing the wrong hat for the task in front of them. Writing the roles down does not require separate people to fill them. It requires being honest about which hat is on when the giving module is open.
The same logic that keeps a church directory from turning into gossip applies here: access is not the risk by itself. Access without a reason is. A small church can keep giving records genuinely private with nothing more sophisticated than a clear, written answer to one question — who looks, and why — kept up to date as your team changes.